<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue with deny snmpv1 / policy-map no match in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/issue-with-deny-snmpv1-policy-map-no-match/m-p/4184669#M1075890</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem on a ASA 5505.&lt;BR /&gt;I want to preclude the version 1 of SNMP.&lt;/P&gt;&lt;P&gt;First i tried the command "snmp deny version 1" but it didn't work.&lt;/P&gt;&lt;P&gt;________________________&lt;/P&gt;&lt;P&gt;Then, i tried this configuration :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(config)#snmp-map nov1here&lt;/P&gt;&lt;P&gt;(config-snmp-map)# deny version 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(config)# access-list aclnov1here extended permit udp any any eq snmptrap&lt;/P&gt;&lt;P&gt;(config)# access-list aclnov1here extended permit udp any any eq snmp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(config)# class-map snmp-block-nov1here&lt;/P&gt;&lt;P&gt;(config-cmap)# match access-list aclnov1here&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(config-cmap)# policy-map policynov1here&lt;/P&gt;&lt;P&gt;(config-pmap)# class snmp-block-nov1here&lt;/P&gt;&lt;P&gt;(config-pmap)# inspect snmp nov1here&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(config-pmap-c)# service-policy policynov1here interface test&lt;/P&gt;&lt;P&gt;__________________&lt;/P&gt;&lt;P&gt;But now when I do :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#show service-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see the policy does not match with packets and neither does the ACL. I can also always request in version 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is someone see where my problem is ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 07 Jan 2021 15:21:08 GMT</pubDate>
    <dc:creator>Aliminna</dc:creator>
    <dc:date>2021-01-07T15:21:08Z</dc:date>
    <item>
      <title>Issue with deny snmpv1 / policy-map no match</title>
      <link>https://community.cisco.com/t5/network-security/issue-with-deny-snmpv1-policy-map-no-match/m-p/4184669#M1075890</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a problem on a ASA 5505.&lt;BR /&gt;I want to preclude the version 1 of SNMP.&lt;/P&gt;&lt;P&gt;First i tried the command "snmp deny version 1" but it didn't work.&lt;/P&gt;&lt;P&gt;________________________&lt;/P&gt;&lt;P&gt;Then, i tried this configuration :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(config)#snmp-map nov1here&lt;/P&gt;&lt;P&gt;(config-snmp-map)# deny version 1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(config)# access-list aclnov1here extended permit udp any any eq snmptrap&lt;/P&gt;&lt;P&gt;(config)# access-list aclnov1here extended permit udp any any eq snmp&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(config)# class-map snmp-block-nov1here&lt;/P&gt;&lt;P&gt;(config-cmap)# match access-list aclnov1here&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(config-cmap)# policy-map policynov1here&lt;/P&gt;&lt;P&gt;(config-pmap)# class snmp-block-nov1here&lt;/P&gt;&lt;P&gt;(config-pmap)# inspect snmp nov1here&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(config-pmap-c)# service-policy policynov1here interface test&lt;/P&gt;&lt;P&gt;__________________&lt;/P&gt;&lt;P&gt;But now when I do :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;#show service-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can see the policy does not match with packets and neither does the ACL. I can also always request in version 1.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is someone see where my problem is ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Jan 2021 15:21:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/issue-with-deny-snmpv1-policy-map-no-match/m-p/4184669#M1075890</guid>
      <dc:creator>Aliminna</dc:creator>
      <dc:date>2021-01-07T15:21:08Z</dc:date>
    </item>
  </channel>
</rss>

